Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,206 CVEs tagged with CWE-4341,480 Critical, 1,614 High, 875 Medium, 236 Low, 1 Unrated.

CVE-2024-58349

Published Jun 8, 2026

WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient valida…

CVSS 9.3 · Critical
evidence mentions
2

CVE-2024-58348

Published Jun 8, 2026

WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.…

CVSS 9.3 · Critical
evidence mentions
4

CVE-2026-11474

Published Jun 8, 2026

A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown function of the file service/Regis…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-7537

Published Jun 6, 2026

The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is…

CVSS 7.2 · High
evidence mentions
11
Buzz score
44.9

CVE-2026-46400

Published Jun 5, 2026

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functionality in HAXCMS PHP only valid…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11419

Published Jun 5, 2026

A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-5411

Published Jun 5, 2026

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versio…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-46392

Published Jun 5, 2026

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11344

Published Jun 5, 2026

A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration Form.…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-11333

Published Jun 5, 2026

A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. The impacted…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-42538

Published Jun 4, 2026

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not properly validate uploaded files…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-10807

Published Jun 4, 2026

A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10806

Published Jun 4, 2026

A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation o…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-40548

Published Jun 1, 2026

SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate user…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-10205

Published Jun 1, 2026

A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systparam/softlogo/upload.jsp. Such mani…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
27.9

CVE-2026-10172

Published May 31, 2026

A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/co…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2018-25409

Published May 30, 2026

SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. A…

CVSS 8.7 · High
evidence mentions
4
Buzz score
32.6

CVE-2018-25388

Published May 29, 2026

HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload…

CVSS 8.7 · High
evidence mentions
4
Buzz score
32.6

CVE-2026-39292

Published May 29, 2026

Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary fi…

CVSS 7.3 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-10072

Published May 29, 2026

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbi…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-10071

Published May 29, 2026

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-30761

Published May 28, 2026

An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a…

CVSS 7.3 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-9227

Published May 28, 2026

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json functio…

CVSS 8.8 · High
evidence mentions
10
Buzz score
44.0

CVE-2026-9009

Published May 28, 2026

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content fun…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-42879

Published May 27, 2026

FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability exists in FacturaScripts' produ…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Showing 126-150 of 4,206 CVEsPage 6 of 169